---
title: "Retrieve"
description: "Read back the offloaded cohort the Receiver diverted from the log analyzer into the customer-owned S3 bucket."
icon: material/bucket-outline
---

Read back the cohort the [Receiver](../../../receiver/) diverted from the log analyzer into a customer-owned S3 bucket (fingerprinted by log pattern, indexed by Bloom filter). When a pattern carries an `offload` action, those events flow to the bucket instead of the log analyzer.

The [Retriever](../../../retriever/) fetches them back on demand, byte-range-scoped, reading the bucket in place rather than copying or re-ingesting. The bucket stays in the customer's account.

!!! tenx-ask "You"

    pull `payment_retry` for `acme-corp`, 90d back

!!! tenx-answer "Log10x"

    412 events match the tenant filter, pulled directly from S3. Time-bucketed series available, or raw events.

!!! tenx-ask "You"

    30d series of `Payment_Retry`, hourly, by tenant

!!! tenx-answer "Log10x"

    720 hourly buckets, broken down by tenant. ~8B events in the window, so per-bucket counts are sampled estimates; shape and tenant ranking stay reliable.

!!! tenx-ask "You"

    what's in the overflow bucket this month?

!!! tenx-answer "Log10x"

    3 patterns · 12.4 GB total · top grower +18%/week. Fetch any of them back with a query.

| You ask | Example answer |
|---|---|
| [pull `payment_retry` for `acme-corp`, 90d back](retriever-query.md) | Raw events, count rollups, time-bucketed series, pulled directly from S3. |
| [30d series of `Payment_Retry`, hourly, by tenant](retriever-series.md) | A time series across the full window, broken down by tenant. |
| [what's in the overflow bucket this month?](overflow-contents.md) | 3 patterns · 12.4 GB total · top grower +18%/week. |

## :material-check-decagram-outline: Prerequisites

These tools require the [Retriever](../../../retriever/) deployed, with at least one pattern assigned an `offload` action via `log10x_configure_engine`.
